How Bugcrowd and the Ethical Hacker Community are rewriting the rules of cybersecurity

How Bugcrowd and the Ethical Hacker Community are rewriting the rules of cybersecurity

Dave Gerry, CEO of Bugcrowd, and Ethical Hacker Justin Gardner (AKA Rhynorater) from the Bugcrowd platform, offer executive and hacker perspectives on addressing the mindset shift required for CISOs to embrace crowdsourced security as a core defence mechanism in an era dominated by fast-moving, AI-driven threats.

Dave Gerry, CEO, Bugcrowd

How has Bugcrowd evolved its approach to crowdsourced cybersecurity to stay ahead of emerging threats?

We’ve obviously had to change a lot over the last 12 years to help our customers stay ahead of a rapidly changing threat landscape. 

I think the biggest thing that we’ve seen is how we engage with the crowd, how we leverage the ingenuity that exists there around giving customers real time access to the best security experts in the world. 

When we first started in this business, it was all about helping customers identify bugs in their applications. It was bug bounty programs that quickly transitioned into vulnerability disclosure programs, where the crowd had the ability to apply some of the regulatory requirements. 

And now as we fast forward through 2025, customers are leveraging the crowd for things like AI bias assessments – understanding the bias that exists in AI models they’re either using or developing. They’re leveraging us to do security testing against AI models. So as we’ve moved forward into the offensive security testing space we’ve seen more around Pen-Testing-as-a-Service, red teaming and helping to give customers access to the resources that they need because they’re facing more threats today than they’ve ever seen before.

What distinguishes Bugcrowd’s platform from traditional vulnerability management solutions?

It all comes back to the crowd. If you look at a traditional vuln management platform, it’s based on automation and scanners. 

They play a role, and they’re good for finding what I’ll call the ‘low hanging fruit of security issues’ but really, when you want to start to get visibility into how a hacker thinks about your environment, or how a bad actor would ultimately try to break into your business or organisation, you need to leverage the power that exists within the crowd.

The best way to find a security threat is to have somebody ultimately come in and manually look for one. And that’s really what separates our platform from a traditional vuln management platform, and there’s plenty of those on the market, and again, they play an important role, but we believe that we’re fundamentally different in the results and outcomes we help drive for our customers.

Justin Gardner AKA Rhynorater, Ethical Hacker

What initially attracted you to Bugcrowd’s platform over other options?

Bugcrowd is one of the best bug bounty platforms out there because of its top-notch programs and its commitment to high-quality triage services.  You can see from the way that each ticket is dealt with that the team truly cares about the hackers that power The Crowd.

What differentiates Bugcrowd’s approach from a hacker’s perspective – especially around communication, payouts and professionalism?

Bugcrowd has excellent communication with hackers, both on their reports and out of band. They do a great job engaging with the community and are always available if an issue pops up in a bug bounty report.  The payout process with Bugcrowd is always quick and painless, and Bugcrowd’s programs boast some of the highest bounties available. Bugcrowd staff are always professional and does a great job standing up for the hacker in even the most difficult of circumstances.

Dave Gerry, CEO, Bugcrowd

How is Bugcrowd using AI to enhance its platform’s accuracy and scalability?

AI has hit every part of our business. For a long time, we’ve been leveraging Machine Learning to match exactly the right hacker at exactly the right time with the right customer problem through our CrowdMatch technology. And since then, we’ve baked this into everything from sales and go-to-market. Sales reps are using it for automated messaging and emails and helping them scale and do what they do every day. 

Our development teams are leveraging AI to become more productive and efficient. We’re leveraging AI for customers with some of the offerings that I talked about earlier. But we are also helping to start thinking about, how does AI help vulnerability verification and some of the triage work that we do to help customers get visibility into vulnerabilities as quickly as possible

One of the challenges in our space is that when somebody – a hacker on our platform for instance – identifies a vulnerability, you need to make sure that gets back to the customer as quickly as possible so they can remediate it and/or, at least in the interim, mitigate the threat that comes with that vulnerability. 

The faster we can triage and verify whether it’s a real vulnerability, understand how critical it is, and determine how the customer should think about fixing it in their environment, the better.

So we’re starting to look at how we can leverage AI to do some of that work faster and to enable and empower our manual team of triagers – the humans – to focus on the most critical vulnerabilities, while allowing AI to filter out some of that noise.

With AI-driven cyberthreats accelerating, how is Bugcrowd helping organisations respond faster and smarter?

What’s really interesting in the market today is that threat actors are increasingly more sophisticated. It’s harder than ever to differentiate a nation state actor from a cybercriminal gang. The cybercriminal gang is now acting with a level of sophistication in their attacks that we haven’t seen before.

A lot of that is driven by AI. Any of us can very quickly become a talented cybercriminal just by leveraging AI and having it develop some of that. A great example is when patches come out – AI can quickly reverse engineer them to understand where an exploit exists, build an exploit package for it, and execute it.

 What used to take an individual a week to do, AI is now doing in an hour. So as we think about how we help our customers – really simply, it’s about acting as an extension of their team. The defender has been outmatched for years, and AI is only accelerating the asymmetry that exists in that kind of battlefield. Helping to bring ethical security researchers to bear on behalf of customers is something they’re getting a lot of value from, and we’re starting to level the playing field.

Justin Gardner AKA Rhynorater, Ethical Hacker

What tools or AI techniques do you use to improve your testing capabilities?

The use of AI is really revolutionising bug bounty at the moment. Tools like ChatGPT, Claude, Cursor, Shift and many others have become pivotal to the methodology of the hackers on the frontlines – the bug bounty hunters. A lot of hackers nowadays fear that AI will greatly impact their job, but the true hackers know that AI is just another tool in their toolkit and will adapt to use it appropriately. AI certainly cannot be ignored, it must be assimilated into our workflows and make us more efficient.

What do you wish more companies understood about working with ethical hackers?

In a lot of ways, the bug bounty hunter is an extension of your security team. Sure, you can’t give us the keys to the kingdom, but any additional insight and access you can provide will reduce the friction to finding a vulnerability and make your bug bounty program stand out from the pack.

Another big thing is that we’re more than just a ticket – treating bug bounty hunters like humans will go a long way with building rapport and making sure your program always has bugs in the queue.

Dave Gerry, CEO, Bugcrowd

What are the biggest misconceptions among security leaders about crowdsourced security – and how do you address them?

There’s always this misconception that a hacker is somebody with a hoodie in the dark in the basement and I think what we’ve really tried to do is shine a light on the amazing skill set that exists, the fact that these are professionals that have full time jobs in many of the top brands in the world. 

We’ve tried to shed a light on the diversity that exists within that group. One of the things I’m most proud of is seeing, every year in our Inside the Mind of the Hacker report, what percentage of the population – what percentage of the crowd – are kids under 18, who are self-taught, doing this to learn new skills. Maybe it’s something they ultimately leverage in a university program, or maybe they skip university altogether and go directly into working in cyber.

I think we’ve had this misconception as a society that hackers are bad, and I think what we’ve helped to do is shine a light to say these are people that are ultimately going to help protect you that are an extension of your team, and we can do that in a few different ways. One is we try to put hackers front and centre. At a recent event we were trying to show, ‘Hey, these are really smart, capable, talented folks that ultimately have the ability to make impactful changes and differences for our customers’, and we’re going to continue pushing that forward. 

We believe that for organisations to be more secure, they have to leverage the power of the ethical security research community, and we’re the way in which they can do that. 

For CISOs sitting on the fence, what’s your advice for making their first move into crowdsourced testing?

Don’t wait. You’re missing out if you’re not leveraging the power of the crowd. The analogy I like to use here is: if you’re not working with the crowd, you can guarantee that the bad actor is already doing the testing for you. So you’d better leverage the power and ingenuity that exists within the hacker community to find those before the bad actors do. Very simply, don’t wait – because you’re falling behind.

Browse our latest issue

Intelligent CISO

View Magazine Archive